Guide
GDPR compliance checklist for technology companies outside Europe
Reviewed 2026-08-07
Short answer
The GDPR can reach a company with no EU office when it offers goods or services to people in the EU or monitors their behaviour there. It can also arrive through a contract when a European customer gives the company personal data to process. A useful checklist must keep those direct and customer-driven routes separate rather than treating a country, certification or contract template as the answer.
See the full 10-step checklist below.Why this matters
- Who should care
- Companies processing personal data in EU-related contexts.
- Typical trigger
- Direct GDPR territorial-scope conditions, or an EU customer's own processing requirements.
- What buyers may ask for
- DPAsubprocessor informationsecurity measurestransfer safeguards
Where this fits
01
Your company
Processes personal data reachable by EU data-protection law, directly or on behalf of an EU customer.
02
EU customer
May be a controller that pushes GDPR obligations down to you through a Data Processing Agreement.
03
Person in the EU
Whose data is involved: this is what determines whether GDPR's territorial scope applies at all.
Who this is relevant to
This guide is for SaaS, platforms, marketplaces and technology services operating outside Europe while serving EU people or processing personal data for EU customers.
It is also useful for teams that have just received a data processing agreement, transfer assessment or privacy questionnaire from a European buyer.
- Products used by people located in the EU
- Vendors processing customer records or support data for a European business
- Teams mapping cloud, engineering and subprocessor access to EU-origin data
- Companies preparing security, privacy and transfer evidence for a European deal
Two ways the GDPR can reach a company outside Europe
The GDPR can apply directly when a company offers goods or services to people located in the EU or monitors their behaviour there. An EU office is not required for either route.
A separate customer-driven route exists when an EU customer gives the company personal data to process on its behalf. The resulting processor relationship is contractual, but the customer is required to put prescribed terms and controls in place.
Accessibility alone is not the same as targeting, and a country of incorporation does not decide applicability. The facts about people, activities, roles and data flows matter.
Direct application vs customer flow-down
A direct obligation can be pursued by a supervisory authority independently of one customer relationship. A customer-driven obligation is experienced through the contract and the evidence the customer needs to manage its own obligations. One company can have both roles for different data sets.
- Direct: the company determines purposes or targets people in the EU in a relevant way
- Customer-driven: the company processes data on documented instructions from a European customer
- Both: marketing, product and customer data can create different roles at the same time
What European customers typically ask you to produce
European buyers rarely ask “are you GDPR compliant?”. They ask for artefacts, and the deal moves at the speed you can produce them.
- A signed data processing agreement on their paper, or a credible one on yours
- A current subprocessor list, with a mechanism for notifying changes
- Where personal data is stored and which countries your staff access it from
- Your technical and organisational security measures, in writing
- A breach notification commitment with a defined timeframe
- A named privacy contact who can answer questions without escalation
- Your position on international transfers, and any assessment behind it
- Evidence that data subject requests reaching your customer can be actioned in your system
Common misconceptions
- “We have no EU entity, so the GDPR cannot apply to us.”
- Establishment is one route into scope, not the only one. Targeting people in the EU or monitoring their behaviour brings a non-EU company into scope directly.
- “We are PDPA compliant, so we are essentially there.”
- The PDPA gives you a real head start: an inventory, a named owner, breach processes. But the scope, the individual rights, the lawful basis analysis and the documentation a European buyer expects all differ. Treat the PDPA as foundation, not equivalence.
- “We are B2B, so we do not process personal data.”
- Business contact details, user accounts, support tickets, session recordings and product analytics are all personal data when they relate to identifiable people.
- “Our cloud provider is certified, so transfers are covered.”
- Your provider's certifications concern their own operations. The transfer position for data you receive is yours to establish, and your customer will ask you for it.
- “Signing Standard Contractual Clauses closes the transfer question.”
- Clauses are one possible mechanism, and using them generally requires an assessment of the destination. Do not promise a mechanism in a questionnaire before you have established it is the right one.
Practical checklist
- 01Establish whether you are a controller, a processor, or both, separately for each dataset you hold
- 02Write down which of your activities involve people located in the EU, and why
- 03Map where EU personal data is stored and from which countries it is accessed, including by your own engineers
- 04Prepare a data processing agreement you can offer, rather than only reacting to your customer's
- 05Maintain a subprocessor register you can send without editing it first
- 06Document your security measures at a level of detail a buyer's security team will accept
- 07Define your breach detection and notification path, with a timeframe you can actually meet
- 08Name a privacy owner internally, even if the role is part-time
- 09Establish your transfer position before a buyer asks. Do not improvise it in a questionnaire
- 10Check whether your website and product use cookies or device storage that require consent
Evidence to assemble before a European deal
Work dataset by dataset: identify the role, the people involved, where data is stored and accessed, the subprocessors involved, and the security and breach processes that support the service.
Treat international transfers as an assessment question rather than assuming that a familiar contract or provider certification settles it. Keep the reasoning and supporting evidence with the relevant data flow.
The checklist is a readiness aid. It does not certify compliance or determine whether the GDPR applies to a particular company.
Cookies and device storage are a separate rulebook
Consent for cookies, SDKs and similar device storage comes from the ePrivacy Directive, implemented in national law, not from the GDPR itself. A Singapore company can be broadly in order on data protection and still be non-compliant on the consent banner in its EU-facing product.
Official EU sources
Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.
Regulation (EU) 2016/679 — General Data Protection Regulation · Read on EUR-Lex (CELEX 32016R0679)Verified 2026-08-17
Directive 2002/58/EC — ePrivacy Directive · Read on EUR-Lex (CELEX 32002L0058)Verified 2026-08-17
RegulationsMethodologySee what the EU Readiness Pack includes
Mini-check: does this reach you?
Three questions. Your answers carry into the full assessment, so nothing is asked twice.